CRA incident & vulnerability reporting has applied since 11 September 2026 — — including products already on the EU market.
For makers of software and connected products sold into the EU

When the 24-hour clock starts, you won't have time to figure out the process. Have it on the shelf.

Since 11 September 2026, the EU Cyber Resilience Act has required manufacturers to file an early warning within 24 hours of learning about an actively exploited vulnerability or severe incident, a fuller report at 72 hours, and a final report after that. The EU's own SME survey says practical templates are the #1 thing companies are missing — and they haven't been provided. This pack is those templates.

Download a free 4-page sample (PDF) →

24hearly warning
72hnotification
14d / 1mofinal report
Get the pack — $390

Not sure yet? Download a free 4-page sample (PDF) — see exactly what you're buying.

Instant download · 14-day unconditional refund · includes the Dec 2027 documentation roadmap

Secure checkout by Polar (merchant of record; card processing by Stripe) · VAT handled · instant download · edition 1.2, current to 20 August 2026. Question first? esau@trykilde.com — a person answers within one business day.

Who this hits (it's broader than most teams think)

Software with EU users"Products with digital elements" covers software placed on the EU market — not just IoT hardware. The pack's triage tells you in minutes whether and how you're in scope.
Products you already shippedThe September reporting duty attaches to products on the market today. There is no grandfathering to hide behind.
Non-EU makersSelling into the EU puts you in scope wherever you're incorporated — and your EU importers and distributors are about to start asking for your paperwork anyway.
Small teams without a compliance personThe obligations assume someone knows the process. The pack IS the process, written down, with every form pre-structured.

What's in the pack

  • Scope triage — are you a manufacturer, importer, distributor, or open-source steward, and which product class are you in? A 15-minute worksheet with the exclusions mapped.
  • The reporting runbook — the heart of the pack: trigger definitions in plain language, a report/don't-report decision tree with counsel-escalation points, per-stage checklists mapped to ENISA's published field matrix, and the Single-Reporting-Platform registration runbook current to ENISA's 31 July / 3 August guides — EU-Login pre-steps, the primary/backup user flow (and its 7-day invite expiry), the "you can report while validation is pending" rule, plus a contingency route if the platform slips.
  • Coordinated vulnerability disclosure policy — the CVD policy the Act expects, plus security.txt and an intake workflow you can run from a shared inbox.
  • Support-period & end-of-life templates — the determination worksheet and the public statements buyers and surveillance authorities look for.
  • Technical-documentation skeleton — the full Dec 2027 file structure with per-section prompts, so the folder that takes months starts today.
  • SBOM primer — what's expected and how to generate one for npm, pip, cargo, and container stacks.
  • Evidence log + edge-case FAQ — SaaS boundaries, open-source components, upstream suppliers.

PDF + editable filesImporter/distributor annex availableUpdate tracker through Dec 2027

See inside

The first pages of the actual pack, edition 1.2, current to 20 August 2026. Open the free 4-page sample (PDF) — no email needed.

CRA Reporting-Ready Pack — page 1CRA Reporting-Ready Pack — page 2CRA Reporting-Ready Pack — page 3
US$390 one-off · instant download

The reporting duty is live: every in-scope product already on the EU market is on the 24-hour clock today (Art 69(3)). Updated August 2026 against ENISA's newly published reporting-platform guides.

Get the pack — instant download

Not sure yet? Download a free 4-page sample (PDF) — see exactly what you're buying.

14-day unconditional refund — email esau@trykilde.com, no questions asked, refunded the same business day. How it works.
Not ready for the full pack? Start with The CRA 24-Hour Reporting Drill — US$39.A 5-page slice that fully solves one job: the decision that starts the clock, the routing you settle once, and the 24-hour early-warning form with a worked example. The US$39 is credited against the full pack within 30 days. Instant download, 14-day refund.

Get it — US$39

Secure checkout by Polar (merchant of record; card processing by Stripe) · VAT handled · instant download · edition 1.2, current to 20 August 2026. Question first? esau@trykilde.com — a person answers within one business day.

Questions we'd ask too

Is this legal advice or a conformity assessment?

Neither. It's an implementation pack — organized information, templates, and runbooks built from the regulation and official guidance, with citations and dates on every claim. Your counsel and (where required) notified bodies still do their jobs; this makes both dramatically cheaper.

We're tiny. Does the EU really expect this from us?

The reporting duties apply to manufacturers of in-scope products regardless of size — and the EU's own agency documented that SMEs lack exactly these templates. Small teams are who this pack exists for.

Isn't the CRA a 2027 problem?

The full essential requirements land 11 December 2027 — but the reporting duties have applied since 11 September 2026, and they cover products already on sale. The pack handles the live duty now and gives you the 2027 folder structure to grow into.

What if official templates come out later?

Then the tracker folds them in and your process gets even easier — you keep the operational runbook, the policies, and the evidence trail, which official forms don't provide.

Why trust this pack

Read from the primary source, not summariesEvery regulatory claim is taken from the instrument itself — the Official Journal text, the regulator's own published guidance, the framework document — not from a secondary explainer. Where a pack turns on a list (product categories, control sets, banned practices), that list was read from the source document item by item and checked against it again before release.
Every claim carries a dateEach pack states the date its research was verified, and each page in it is stamped with what it is current to. Where a fact is contested, provisional or merely announced rather than in force, it says so in the text instead of being smoothed over.
Changes are published, not quietly patchedWhen a tracked instrument moves, the change is dated in a public changelog and on the deadline radar. You can see what changed and when, before you buy and after.
Independent, and explicit about itKilde is not affiliated with, endorsed by or approved by any regulator, standards body or scheme operator. Where a pack covers a private framework, it identifies controls by number and title and directs you to the operator's own document.
See it before you payFour real pages of every pack are free — the actual cover and opening section, not a brochure. Every purchase carries a 14-day unconditional refund.

Kilde sells document templates and organised regulatory information. It is not a law firm and does not provide legal advice; buying a pack does not create an attorney-client relationship. Built and maintained by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About Kilde · Verification log · Refunds · Terms · Privacy · esau@trykilde.com